AkilIQ Data Processing Agreement
Version: [VERSION]
Effective date: June 1, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between AkilIQ Inc., trading as AkilIQ (“AkilIQ”), and the customer identified in the applicable order form, subscription, or services agreement (“Customer”).
This DPA applies where AkilIQ processes Personal Data on behalf of Customer in connection with the AkilIQ services.
Draft notice: This template contains placeholders and should be reviewed by qualified legal counsel before production use, particularly after the AkilIQ legal entity, hosting regions, subprocessors, security controls, and international-transfer arrangements are finalized.
1. Definitions
For this DPA:
Applicable Data Protection Law means applicable privacy and data-protection legislation governing the Processing, including the GDPR and UK GDPR where applicable.
Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach, and Supervisory Authority have the meanings given by Applicable Data Protection Law.
Customer Data means data submitted to or processed through the Services by or for Customer.
GDPR means Regulation (EU) 2016/679.
Services means the AkilIQ products and services provided to Customer.
Subprocessor means a processor engaged by AkilIQ to Process Personal Data on behalf of Customer.
2. Roles of the Parties
Where AkilIQ Processes Personal Data contained in Customer Data on behalf of Customer:
- Customer is the Controller or a Processor acting on behalf of another Controller; and
- AkilIQ is the Processor or Subprocessor, as applicable.
Each party will comply with obligations applicable to it under Applicable Data Protection Law.
Customer is responsible for ensuring that its instructions to AkilIQ are lawful.
3. Details of Processing
Subject matter
Provision of the AkilIQ Services, including data ingestion, storage, structuring, transformation, monitoring, API delivery, AI-assisted processing, procurement-intelligence functionality, support, and related functionality selected by Customer.
Duration
For the duration of the Services and any agreed retention or deletion period.
Nature and purpose
Processing necessary to provide, secure, maintain, support, and operate the Services according to Customer’s documented instructions.
Categories of Data Subjects
Depending on Customer’s use:
- Customer employees and Authorized Users;
- Customer clients and prospects;
- suppliers;
- contractors;
- business contacts;
- tender/procurement contacts;
- persons represented in Customer documents or datasets;
- other Data Subjects whose Personal Data Customer lawfully submits.
Types of Personal Data
Depending on Customer configuration:
- identity and contact data;
- employment/business information;
- account identifiers;
- financial/business information;
- document contents;
- database records;
- API payloads;
- technical identifiers;
- procurement-related information;
- other Personal Data selected and submitted by Customer.
Special Categories
Customer must not submit special-category or highly sensitive Personal Data unless the Services are appropriate for that Processing, Customer has a lawful basis, and any additional contractual/security requirements have been agreed.
Approved special-category processing, if any: [INSERT OR “NONE BY DEFAULT”]
4. Customer Instructions
AkilIQ will Process Personal Data only on documented instructions from Customer, including instructions contained in:
- the applicable agreement;
- this DPA;
- Customer’s use and configuration of the Services;
- authorized support requests;
- written instructions accepted by AkilIQ.
If AkilIQ is required by applicable law to Process Personal Data contrary to Customer’s instructions, AkilIQ will inform Customer before Processing unless prohibited by law.
If AkilIQ reasonably believes an instruction violates Applicable Data Protection Law, it will inform Customer and may suspend the affected Processing while the parties address the issue.
5. Confidentiality
AkilIQ will ensure persons authorized to Process Personal Data are subject to appropriate confidentiality obligations.
Access will be limited to persons who require it for authorized purposes.
6. Security
AkilIQ will implement and maintain appropriate technical and organizational measures designed to protect Personal Data, taking into account the state of the art, implementation costs, nature/scope/context/purpose of Processing, and risks to individuals.
Measures may include, as applicable:
- encryption in transit;
- encryption at rest;
- logical access controls;
- least-privilege authorization;
- authentication controls;
- tenant isolation;
- credential and secret management;
- audit/security logging;
- backup and recovery controls;
- vulnerability and dependency management;
- secure development practices;
- incident response;
- availability and resilience controls.
The final production security schedule should be maintained in Annex II.
7. Subprocessors
Customer authorizes AkilIQ to engage Subprocessors subject to this DPA.
AkilIQ will:
- maintain a current Subprocessor list at [SUBPROCESSOR URL];
- impose appropriate data-protection obligations on Subprocessors;
- remain responsible for Subprocessor performance to the extent required by Applicable Data Protection Law;
- provide notice of intended material Subprocessor changes where required by the applicable agreement or law.
Objections
Where Customer has a legally or contractually applicable objection right, Customer may submit a reasonable data-protection objection within [NUMBER] days after notice.
The parties will work in good faith to find a commercially reasonable resolution.
If no reasonable solution is available, applicable termination rights will be governed by the services agreement/DPA and mandatory law.
8. Data Subject Requests
Taking into account the nature of the Processing, AkilIQ will provide reasonable assistance to Customer with requests from Data Subjects concerning rights under Applicable Data Protection Law.
If AkilIQ receives a request relating to Personal Data controlled by Customer, AkilIQ will ordinarily refer the requester to Customer and will not independently respond except as required by law or authorized by Customer.
Customer remains responsible for responding to requests as Controller.
9. Personal Data Breaches
AkilIQ will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed on Customer’s behalf where notification is required by Applicable Data Protection Law.
To the extent reasonably available, AkilIQ will provide information to assist Customer in understanding:
- the nature of the breach;
- categories and approximate number of affected Data Subjects;
- categories and approximate number of affected records;
- likely consequences;
- measures taken or proposed to address the breach.
Information may be provided in phases as an investigation develops.
Notification does not constitute an admission of fault or liability.
10. Data Protection Impact Assessments and Regulatory Assistance
Taking into account the nature of Processing and information available to AkilIQ, AkilIQ will provide reasonable assistance with:
- data-protection impact assessments; and
- prior consultation with Supervisory Authorities,
where required for Customer’s use of the Services.
Any extraordinary assistance beyond standard compliance information may be subject to reasonable fees where permitted and agreed.
11. International Transfers
Where AkilIQ transfers European Personal Data to a country that requires a transfer mechanism, the parties will use an appropriate lawful mechanism.
This may include:
- an adequacy decision;
- European Commission Standard Contractual Clauses (“SCCs”);
- the UK Addendum or International Data Transfer Agreement;
- another valid mechanism.
Where SCCs are required, the applicable SCC module will depend on the parties’ roles.
EU transfer mechanism: [INSERT]
UK transfer mechanism: [INSERT]
Primary processing regions: [INSERT]
AkilIQ will provide information reasonably necessary for applicable transfer assessments.
12. Data Location
Customer Data may be Processed in locations described in the applicable order form, product configuration, Subprocessor list, or enterprise agreement.
Specific residency commitments apply only where expressly agreed.
Available deployment models may include managed cloud, dedicated infrastructure, customer-controlled databases, and on-premise deployments.
13. AI Processing
Where Customer enables AI Features, Personal Data may be Processed by AkilIQ or approved AI Subprocessors as necessary to provide those features.
Private Customer Data will not be used to train shared or general-purpose AkilIQ AI models by default.
Any materially different use for model training will require an appropriate lawful basis and any customer authorization promised by the applicable agreement.
AI Subprocessors processing Customer Personal Data must be included in AkilIQ’s Subprocessor governance where required.
14. Return and Deletion
Upon termination or expiry of the Services, AkilIQ will, at Customer’s choice and subject to the applicable agreement:
- provide available mechanisms for return/export of Customer Data; and/or
- delete Personal Data Processed on Customer’s behalf.
Deletion may be subject to:
- agreed export windows;
- backup retention cycles;
- legal retention obligations;
- technical requirements for secure deletion.
Personal Data remaining temporarily in backups will remain protected and will not be restored for ordinary Processing except where necessary for disaster recovery or legal requirements.
Standard export window: [INSERT]
Production deletion period: [INSERT]
Backup deletion period: [INSERT]
15. Audit and Compliance Information
AkilIQ will make information reasonably necessary to demonstrate compliance with processor obligations available to Customer.
AkilIQ may satisfy routine audit requests through:
- security documentation;
- compliance reports;
- questionnaires;
- independent audit reports/certifications when available.
Where legally required and reasonable documentation is insufficient, Customer may request an audit subject to reasonable confidentiality, security, scheduling, frequency, and scope restrictions.
Customer audits must not compromise other customers’ security or confidentiality.
16. Liability
Liability arising under this DPA is subject to the limitations and exclusions in the applicable services agreement to the extent permitted by Applicable Data Protection Law.
Nothing limits liability that cannot lawfully be limited.
17. Conflict
If this DPA conflicts with the main services agreement regarding Processing of Personal Data, this DPA controls for that subject.
Where applicable SCCs conflict with this DPA, the SCCs control to the extent of the conflict.
18. Governing Law
Except where Applicable Data Protection Law or SCCs require otherwise, this DPA follows the governing-law and dispute provisions of the main services agreement.
Annex I — Processing Details
Customer: [CUSTOMER / AS IDENTIFIED IN ORDER FORM]
Processor: AkilIQ Inc.
Processing activities: [SEE SECTION 3 / CUSTOMIZE]
Duration: [SUBSCRIPTION TERM + RETENTION]
Data subjects: [CUSTOMIZE IF REQUIRED]
Personal data: [CUSTOMIZE IF REQUIRED]
Special categories: [NONE BY DEFAULT / CUSTOMIZE]
Processing frequency: [CONTINUOUS / ON CUSTOMER INSTRUCTION]
Retention: [INSERT]
Annex II — Technical and Organizational Measures
Complete this schedule before production publication.
Access Control
- [MFA STATUS]
- [RBAC IMPLEMENTATION]
- [LEAST PRIVILEGE]
- [ACCESS REVIEW PROCESS]
Encryption
- In transit: [TLS DETAILS]
- At rest: [ENCRYPTION DETAILS]
- Key management: [DETAILS]
Tenant Isolation
- [TENANT ISOLATION MODEL]
- [DATABASE / OBJECT STORAGE ISOLATION]
Logging and Monitoring
- [AUDIT LOGGING]
- [SECURITY MONITORING]
- [LOG RETENTION]
Secure Development
- [CODE REVIEW]
- [DEPENDENCY SCANNING]
- [CONTAINER SCANNING]
- [VULNERABILITY PROCESS]
Availability and Recovery
- [BACKUP FREQUENCY]
- [BACKUP RETENTION]
- [RECOVERY PROCEDURES]
- [DR TESTING]
Incident Response
- [INCIDENT PROCESS]
- [ON-CALL / ESCALATION]
- [BREACH NOTIFICATION PROCESS]
Personnel
- [CONFIDENTIALITY]
- [SECURITY TRAINING]
- [ACCESS OFFBOARDING]
Annex III — Approved Subprocessors
The current list is maintained at:
[SUBPROCESSOR PAGE URL]
Initial list: [TO BE COMPLETED BEFORE PRODUCTION]
Annex IV — International Transfer Terms
EU SCCs required: [YES / NO / DEPENDS ON REGION]
Applicable SCC module: [MODULE 2 / MODULE 3 / OTHER]
UK Addendum/IDTA required: [YES / NO]
Additional safeguards: [INSERT]
Where required, the parties will complete and incorporate the applicable transfer documents.